Manual Action Penalty or Algorithmic Demotion: How to Tell Which One Hit You
· Royking Niba
A manual action is a human decision: somebody at Google reviewed your site, judged it in breach of the spam policies, and applied a demotion that is named in writing inside Search Console. An algorithmic demotion is a scoring outcome: no human looked at you, nothing is named, and a ranking system simply stopped rewarding your pages the way it used to. To tell them apart, open the Manual Actions report in Google Search Console. It is definitive, it takes about thirty seconds, and it is the first fork in every diagnosis I run.
I put it first because it is the most expensive question to get wrong. The two situations require opposite responses, and every week spent on the wrong one is a week of compounding loss. Across the recovery work that has returned over 8 million organic visits for clients, I have never seen a case where skipping this check saved time. I have seen plenty where skipping it cost a month.
Do the thirty-second check before you form a single theory
Search Console, Security and Manual Actions, Manual Actions. You get one of two states. Either the report says no issues detected, or it names one or more actions with a description and a scope. There is no third state, no partial information, no interpretation required. This is the only diagnostic in SEO that returns a genuinely binary answer, so use it before anything ambiguous.
Two things people get wrong here. First, the report is per property, so check the property that actually covers the affected hostname. A URL-prefix property for www and one for the bare domain are separate entities, and a clean report on the wrong property is not a clean report. I use a domain property for exactly this reason. Second, read the scope, not just the label. A partial match applies to specific URLs or a section and tells you where to look. A site-wide match applies to everything and tells you the problem is structural.
If the report names something, stop theorising. You already know the cause, and the rest of this becomes an execution problem rather than an investigative one.
The manual action types, in plain terms
Google publishes the full list, but the descriptions are written for compliance rather than for a person whose traffic vanished on Tuesday. Here is what each one actually means about your site, and what it points you at.
| Manual action | What it means in plain terms | Where the fix lives |
|---|---|---|
| Unnatural links to your site | A reviewer judged part of your inbound profile to be manufactured: bought, exchanged, or built at scale to pass ranking signals. The links point at you. | Off-site. Removal first, disavow for what will not come down. |
| Unnatural links from your site | You are the one selling or placing links. Paid or exchanged outbound links that pass PageRank because they were never qualified with rel="sponsored" or rel="nofollow". | On-site. Your own outbound link graph, including footers, widgets and old sponsored posts. |
| Thin content with little or no added value | Pages that exist without a reason to exist. Doorway pages, scraped or syndicated content with nothing added, thin affiliate pages, auto-generated filler. | On-site. Content strategy, not technical SEO. |
| Cloaking | Googlebot is served different content from the one a user gets. Sometimes deliberate, often the result of a compromised server or an aggressive geo or device rule nobody audited. | Server and template layer. Check the rendered HTML both ways. |
| Sneaky redirects | Users are bounced to a destination the crawler never sees, or mobile users are sent somewhere desktop users are not. Google frequently issues this alongside cloaking as one item. | Redirect rules, injected scripts, third-party ad tags. |
| User-generated spam | Spam posted by other people on your property: forum threads, comment sections, profile pages, unmoderated user listings. Your content is fine. Your moderation is not. | Moderation policy and clean-up of existing UGC. |
| Spammy free host | You operate a free hosting or subdomain service and a significant share of what lives on it is spam. The action can reach the whole host. | Sign-up controls, abuse detection, mass removal. |
| Structured data issues | Markup that does not match what a user sees, marks up content that is not on the page, or claims a rich result type the page is not eligible for. | Templates. Reconcile markup against the structured data documentation and visible content. |
| Site reputation abuse | Third-party content published on your domain mainly to borrow your ranking signals, with little first-party oversight. Rented subfolders, coupon sections, sponsored-post silos. | Editorial control, or removal of the section entirely. |
| Scaled content abuse | Many pages produced primarily to manipulate rankings rather than help people. The method does not matter. AI, human, or a mix, the judgement is about purpose and volume. | Content inventory. Usually a large prune. |
| Expired domain abuse | An expired domain bought for its residual signals and repurposed with content unrelated to what earned those signals. | The domain strategy itself, which often means the domain is not salvageable. |
The report also carries hacked content and pure spam actions, which are the ones that mean the site is compromised or is wholly a spam operation. Every type maps back to a specific clause in Google’s spam policies, and reading the clause matters, because a reconsideration request is judged against it rather than against your explanation.
I spent years running the full lifecycle of expired-domain networks on the other side of this fence, including acquisition, archive.org content recovery and restoration. That is precisely why I can read an expired domain abuse or unnatural links action quickly. You recognise your own former handiwork.
When the report is clean: the three tells of an algorithmic demotion
A clean report does not mean nothing is wrong. It means no human named a breach, so the loss came from scoring. Three signals confirm it, and you want all three before you commit to that reading.
The timing correlates with a confirmed update. Not roughly, precisely. Put your daily clicks against the rollout window on the Search Central blog, and check the Search Status Dashboard for indexing or serving incidents in the same period. A drop that begins mid-rollout and stabilises when the rollout completes is an algorithmic story. A drop that begins on a Thursday with nothing announced anywhere is something else, and quite often it is a technical fault rather than any kind of demotion.
The loss is graded, not binary. Algorithmic demotions move you down. Positions slide from two to seven, from six to fourteen, and the click loss follows the curve. Manual actions tend to remove: pages leave the index or fall so far that they may as well have. If your affected URLs still rank, just worse, and the decline has texture rather than a cliff edge, that is scoring.
The shape is query-class, not sitewide. This is the tell that decides the remediation plan, so it is worth the two days it takes to segment properly. Export your Search Console queries for the eight weeks before and after, classify them by intent and page type, and look at where the loss concentrated. Algorithmic demotions almost always hit a class: commercial comparison queries while informational ones hold, or one content silo while the rest of the site is flat. Uniform loss across every query type and every template points at something sitewide, which means a manual action, a technical fault, or a site-level quality signal.
The two situations demand opposite responses
| Manual action | Algorithmic demotion | |
|---|---|---|
| Who decided | A human reviewer at Google | A ranking system, no human in the loop |
| How you find out | Named in the Manual Actions report, with a message | Nothing. You infer it from your own data |
| What you are told | The violation type and the scope | Nothing specific, ever |
| Shape of the loss | Often binary within the affected scope | Graded, and usually concentrated in a query class |
| Timing | Any day. Not tied to a public announcement | Tracks a confirmed rollout window |
| The exit | Fix, document, file a reconsideration request | No ticket exists. Rebuild quality and wait for a refresh |
| Who controls the clock | You, once the fix is genuinely complete | Google, entirely |
That last row is the one that changes behaviour. A manual action is a closed process with a defined exit. You know the charge, you remediate it, you submit evidence, a reviewer accepts or rejects, and the demotion is lifted. Painful, bounded, and resolvable on a timeline you partly control.
An algorithmic demotion has no counterparty. There is nobody to convince, no queue you are sitting in, and no acceptance event. You rebuild against what Google’s guidance on creating helpful content actually asks for, and then the next evaluation of your site either scores it differently or does not. On the sports-media property I recovered, roughly 45,000 monthly organic visits came back across an August to October window, and none of that was a submission being approved. It was rebuilt quality meeting a re-evaluation. The full sequence is in the spam update recovery case study.
What actually goes in a reconsideration request
Most reconsideration requests are rejected for one reason: they describe intent instead of evidencing change. “We have removed all bad links and will follow the guidelines going forward” is a promise. A reviewer cannot verify a promise, so they verify the site, find the breach still present, and reject. Write the request as a case file, not as an apology.
Three things belong in it, in this order.
- What went wrong and how it happened. Name the practice honestly, including who did it, whether that was a former agency, a freelancer, or you. Reviewers see evasion constantly and it costs you credibility you need for the rest of the document.
- What you changed, itemised and verifiable. Counts and specifics. Number of URLs removed or rewritten, number of referring domains contacted, number removed, number disavowed and why removal failed. Link a shared spreadsheet showing every domain, its status, the date of each outreach attempt and the outcome. On one audit I ran, more than 200 manufactured referring domains had to be documented individually, and that document is what made the case, not the covering paragraph.
- What stops it recurring. The process change. Who approves link acquisition now, what the moderation rule is, what the publishing standard is. One paragraph, concrete.
Do not file until the fix is finished. A request submitted mid-clean-up gets rejected, and while there is no formal penalty for a rejection, you have burned a review cycle and you will wait again. On the links side specifically, the disavow file needs to be uploaded and correct before you submit, and it needs to be the file you can defend rather than a bulk export of everything a tool flagged orange. I set out the inclusion test I use in the disavow file explained.
The most common wasted week in this entire field
Someone loses forty per cent of their traffic to a core or spam update, finds no manual action, and files a reconsideration request anyway. There is nothing to reconsider. The reconsideration process exists solely to review manual actions, so with a clean report there is no case to open, no reviewer assigned, and no reply that will help you. Search Console will not even offer you the form.
The cost is not the submission. It is the seven to fourteen days spent waiting for an answer that is never coming, during which the actual work of rebuilding has not started. I see this often enough that I now treat it as the default failure mode of a self-diagnosed recovery, and it is the reason the manual actions check sits at the top of my sequence rather than somewhere in the middle. The wider order of operations is in my guide to Google penalty recovery.
The mirror-image error is cheaper but still real: assuming an algorithmic cause, spending six weeks rewriting content, and only later discovering an unnatural links action that was sitting in the report the whole time. Nothing you rewrite lifts a manual action. Only remediation plus an accepted request does.
What I would do in the next hour
- Open the Manual Actions report on the property that covers the affected hostname. Note the state and, if there is an action, the exact type and scope.
- If there is an action: read the matching clause in the spam policies, scope the remediation, and set a completion date. Do not touch the reconsideration form until that date passes.
- If the report is clean: pull daily clicks for sixteen weeks and mark the drop against announced rollout windows, then check the Search Status Dashboard for the same dates.
- Either way, segment the loss by page type and query class before you change anything. The shape of the loss tells you which part of the site is actually being judged.
- If the report is clean and the timing matches nothing announced, treat it as a technical fault until proven otherwise. Indexing, canonicalisation and serving errors produce graphs that look exactly like penalties and are far more common.
Thirty seconds of checking decides which of two entirely different projects you are about to run. Do it before you tell anyone what happened, including yourself.